Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mikeysight
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
mikeysight
14d ago
https://krebsonsecurity.com/2026/09/fbi-probes-service-selli... fun times
2.
▲
by
mikeysight
24d ago
I think we just hold a different mental model of the problem, and that's fine. I view the internet as a digital world of destinations, and devices as the vehicles we use to visit those destinations. In the physical world, children shar
3.
▲
by
mikeysight
24d ago
Interestingly enough, many of the age verification laws passed recently in the states and EU explictly require or suggest anonymous or otherwise privacy-preserving technologies in their wording. I share a healthy dose of skepticism and cyni
4.
▲
by
mikeysight
24d ago
Thanks for the thoughts here! The whitelist vs blacklist association is spot on, and despite being practical I think there's an argument to be made that it's a strength, since it takes the onus off of the minor in this case and ad
5.
▲
by
mikeysight
24d ago
as promised, wanted to circle back on a few last items: > Is the document in the encrypted blob accessible by the user? Currently, verified elements of the document are encrypted and persisted but not the entire document. I do think in t
6.
▲
by
mikeysight
24d ago
I forgot to include this but sincerely, thank you for the comments and for giving me an opportunity to answer some very important questions that motivate me.
7.
▲
by
mikeysight
24d ago
I obviously totally disagree (otherwise there'd be no reason for me to keep building), and I'll explain why. Working backwards, I think the device is exactly the wrong place for enforcement. Devices are not individuals and individ
8.
▲
by
mikeysight
25d ago
the service doesn't see the document itself on subsequent verifications but it does receive a signed verification payload containing derived fields in plaintext currently. No ZK proofs at this stage but agreed it would be a great futur
9.
▲
by
mikeysight
26d ago
I wasn't familiar with this protocol, thank you for sharing. I have something similar to this in the works right now along the lines of passkey-bound session keys that can be used without the user being present.
10.
▲
by
mikeysight
26d ago
the recovery flow is scoped to the account but not the encrypted data. if the passkey is lost, the encrypted identity data is lost (by design) and the user has to upload again before new verifications. the account and associations with prev
11.
▲
by
mikeysight
27d ago
Great question, and also thank you for calling this out, because "selfie data" shouldn't be included in that description, since those images are not persisted at all, encrypted or otherwise (editing now). You make a very good
12.
▲
by
mikeysight
28d ago
I wrote up more of the thinking behind this here for those interested: https://loginwithone.com/blog/the-internet-should-be-more-li...
13.
▲
by
mikeysight
28d ago
> ONE still sees identity documents in the clear the first time when it verifies them, right? Otherwise we could upload fakes. Yes that's correct, the identity documents are validated alongside the selfie before the selfie is discar
14.
▲
by
mikeysight
29d ago
also google if you're reading this don't even think about it, patent is pending and my uncle is a lawyer
15.
▲
by
mikeysight
29d ago
check out the demo video! I think you'll like it :) that's the exact user experience (it's built on the same OAuth protocol) but with all underlying data encrypted to your device.
16.
▲
Show HN: Anonymous age verification with passkey-powered encryption
(loginwithone.com)
45 points
by
mikeysight
29d ago
|
27 comments
17.
▲
by
mikeysight
1mo ago
Also fair, and there’s certainly an argument to be had there, but it already is law in many cases. Either way, my belief is that it’s not a better outcome to accept the status quo on the implementation side at the expense of privacy while t
18.
▲
by
mikeysight
1mo ago
That's an interesting thought. One thing that comes to mind is that age-gating is often not a cut and dry boolean granting or denying access to an entire application. It's conceivable and even expected that a social media company
19.
▲
by
mikeysight
1mo ago
Totally fair distinction, and good callout. I agree that open access should be the presumption. The liquor store is not meant here as a metaphor for the internet at large, but rather for how the internet should operate in the specific circu
20.
▲
by
mikeysight
1mo ago
Hi! Author here. This project has been kicking around in my head since I first heard about the webauthn PRF extension in early 2024. I've slowly chipped away at it since, and finally got things to a shareable state over the summer than
21.
▲
The Internet Should Be More Like a Liquor Store
(loginwithone.com)
2 points
by
mikeysight
1mo ago
|
8 comments